Zimbra Releases Patch for Critical Vulnerabilities in Zimbra Collaboration Suite

Views: 187 views

405/69 Thursday, July 23, 2026

Zimbra has released a security update for Zimbra Collaboration Suite (ZCS) version 10.1.20 to address multiple Critical vulnerabilities, including a command injection flaw in the SNMP monitoring component. The vulnerability could allow unauthenticated attackers to execute commands on the operating system of the email server if SNMP notifications are enabled and the Swatchdog service is running.

Reports indicate that this update also fixes multiple Cross-site Scripting (XSS) vulnerabilities in the Classic Web Client, or Classic UI, which could be exploited to execute scripts under certain conditions through attachment filenames, specially crafted fields, or malicious attachments. In addition, the update addresses other vulnerabilities, including an email forwarding restriction bypass tracked as CVE-2026-50055, an access control vulnerability in the EWS extension tracked as CVE-2026-10631, an authorization flaw in mailbox delegation tracked as CVE-2026-50054, and a Server-side Request Forgery (SSRF) vulnerability in the Nextcloud integration.

Administrators using Zimbra should update to ZCS version 10.1.20 as soon as possible, especially on systems with SNMP notifications enabled or services related to monitoring in use. They should also review email forwarding settings, mailbox delegation, and extensions connected to external services. In addition, administrators should inspect logs for abnormal access, unauthorized command execution, suspicious attachments or emails, and email forwarding activity to unknown destinations. At the time of reporting, there were no reports that the vulnerabilities had been actively exploited.

Source: https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/